CVE-2023-45866
published 2023-12-08CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID…
PriorityP338medium6.3CVSS 3.1
AVAACLPRNUINSUCLILAL
EPSS
7.88%
94.1th percentile
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Affected
36 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_17.2_and_ipados | — | — |
| apple | ipados | < 17.2 | 17.2 |
| apple | iphone_os | < 17.2 | 17.2 |
| apple | iphone_os | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | >= 14.0 < 14.2 | 14.2 |
| apple | macos_sonoma | — | — |
| bluez | bluez | >= 0 < 5.55-3.1+deb11u1 | 5.55-3.1+deb11u1 |
| bluez | bluez | >= 0 < 5.66-1+deb12u1 | 5.66-1+deb12u1 |
| bluez | bluez | >= 0 < 5.70-1.1 | 5.70-1.1 |
| bluez | bluez | >= 0 < 5.70-1.1 | 5.70-1.1 |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | bluez | < bluez 5.66-1+deb12u1 (bookworm) | bluez 5.66-1+deb12u1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
osv·2023-12-08·CVSS 7.1
CVE-2023-45866 [HIGH] CVE-2023-45866: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
GHSA
GHSA-qjcj-xg77-6c32: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
ghsa_unreviewed·2023-12-08·CVSS 7.1
CVE-2023-45866 [HIGH] CWE-287 GHSA-qjcj-xg77-6c32: Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HI
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
OSV
CVE-2023-45866: In multiple locations, there is a possible way to inject keystrokes due to improper input validation
osv·2023-12-01
CVE-2023-45866 CVE-2023-45866: In multiple locations, there is a possible way to inject keystrokes due to improper input validation
In multiple locations, there is a possible way to inject keystrokes due to improper input validation. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Microsoft
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection
vendor_msrc·2023-12-12·CVSS 6.3
CVE-2023-45866 [HIGH] CWE-287 Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection and accept HID keyboard reports potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of
Apple
CVE-2023-45866: macOS Sonoma 14.2
vendor_apple·2023-12-11·CVSS 6.3
CVE-2023-45866 [MEDIUM] CVE-2023-45866: macOS Sonoma 14.2
Apple Security Update: About the security content of macOS Sonoma 14.2
Product: macOS Sonoma
Version: 14.2
CVE: CVE-2023-45866
Component: Bluetooth
Impact: An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard
Description: The issue was addressed with improved checks.
Apple
CVE-2023-45866: iOS 17.2 and iPadOS 17.2
vendor_apple·2023-12-11·CVSS 6.3
CVE-2023-45866 [MEDIUM] CVE-2023-45866: iOS 17.2 and iPadOS 17.2
Apple Security Update: About the security content of iOS 17.2 and iPadOS 17.2
Product: iOS 17.2 and iPadOS
Version: 17.2
CVE: CVE-2023-45866
Component: Bluetooth
Impact: An attacker in a privileged network position may be able to inject keystrokes by spoofing a keyboard
Description: The issue was addressed with improved checks.
Ubuntu
BlueZ vulnerability
vendor_ubuntu·2023-12-07
CVE-2023-45866 BlueZ vulnerability
Title: BlueZ vulnerability
Summary: BlueZ could be made to give a physically proximate attacker keyboard and
mouse control of a computer.
It was discovered that BlueZ did not properly restrict non-bonded devices
from injecting HID events into the input subsystem. This could allow a
physically proximate attacker to inject keystrokes and execute arbitrary
commands whilst the device is discoverable.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
vendor_redhat·2023-12-07·CVSS 7.1
CVE-2023-45866 [HIGH] CWE-287 bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
bluez: unauthorized HID device connections allows keystroke injection and arbitrary commands execution
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
A flaw was found in the HID Profile in BlueZ that opens doors for unauthorized connections, especially by devices like keyboards, to inject keystrokes without user confirmation. BlueZ lacks proper restrictions on
Android
CVE-2023-45866: Android Security Bulletin 2023-12-01
CVE: CVE-2023-45866
Severity: CRITICAL
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-294854
vendor_android·2023-12-01·CVSS 6.3
CVE-2023-45866 [MEDIUM] CVE-2023-45866: Android Security Bulletin 2023-12-01
CVE: CVE-2023-45866
Severity: CRITICAL
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-294854
Android Security Bulletin 2023-12-01
CVE: CVE-2023-45866
Severity: CRITICAL
Type: EoP
Affected AOSP versions: 11, 12, 12L, 13, 14
References: A-294854926
[2]
[3]
[4]
[5]
Debian
CVE-2023-45866: bluez - Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID D...
vendor_debian·2023·CVSS 7.1
CVE-2023-45866 [HIGH] CVE-2023-45866: bluez - Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID D...
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Scope: local
bookworm: resolved (fixed in 5.66-1+deb12u1)
bullseye: resolved (fixed in 5.55-3.1+deb11u1)
forky: resolved (fixed in 5.70-1.1)
sid: resolved (fixed in 5.70-1.1)
trixie: resolved (fixed in 5.70-1.1)
No detection rules found.
No public exploits indexed.
Checkpoint
11th December – Threat Intelligence Report
blogs_checkpoint·2023-12-11
CVE-2023-40088 11th December – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th December – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th December, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American Greater Richmond Transit Company (GRTC), which provides services for millions of people, has been a victim of cyber-attack that impacted certain applications and parts of the GRTC network. The Play ransomware gang claimed responsibility for the attack.
Check Point Harmony Endpoint and Threat Emulation prov
Bleepingcomputer
December Android updates fix critical zero-click RCE flaw
blogs_bleepingcomputer·2023-12-04·CVSS 8.4
CVE-2023-40088 [HIGH] December Android updates fix critical zero-click RCE flaw
## December Android updates fix critical zero-click RCE flaw
## Sergiu Gatlan
Google announced today that the December 2023 Android security updates tackle 85 vulnerabilities, including a critical severity zero-click remote code execution (RCE) bug.
Tracked as CVE-2023-40088, the zero-click RCE bug was found in Android's System component and doesn't require additional privileges to be exploited.
While the company has yet to reveal if attackers have targeted this security flaw in the wild, threat actors could exploit it to gain arbitrary code execution without user interaction.
"The most severe of these issues is a critical security vulnerability in the System component that could lead to remote (proximal/adjacent) code execution with no additional execution privileges needed. User int
http://changelogs.ubuntu.com/changelogs/pool/main/b/bluez/bluez_5.64-0ubuntu1/changeloghttp://seclists.org/fulldisclosure/2023/Dec/7http://seclists.org/fulldisclosure/2023/Dec/9https://bluetooth.comhttps://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/profiles/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675https://github.com/skysafe/reblog/tree/main/cve-2023-45866https://lists.debian.org/debian-lts-announce/2023/12/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/77YQQS5FXPYE6WBBZO3REFIRAUJHERFA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2N2P5LMP3V7IJONALV2KOFL4NUU23CJ/https://security.gentoo.org/glsa/202401-03https://support.apple.com/kb/HT214035https://support.apple.com/kb/HT214036https://www.debian.org/security/2023/dsa-5584http://changelogs.ubuntu.com/changelogs/pool/main/b/bluez/bluez_5.64-0ubuntu1/changeloghttp://seclists.org/fulldisclosure/2023/Dec/7http://seclists.org/fulldisclosure/2023/Dec/9https://bluetooth.comhttps://git.kernel.org/pub/scm/bluetooth/bluez.git/commit/profiles/input?id=25a471a83e02e1effb15d5a488b3f0085eaeb675https://github.com/skysafe/reblog/tree/main/cve-2023-45866https://lists.debian.org/debian-lts-announce/2023/12/msg00011.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/77YQQS5FXPYE6WBBZO3REFIRAUJHERFA/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/D2N2P5LMP3V7IJONALV2KOFL4NUU23CJ/https://lists.fedoraproject.org/archives/list/[email protected]/message/77YQQS5FXPYE6WBBZO3REFIRAUJHERFA/https://lists.fedoraproject.org/archives/list/[email protected]/message/D2N2P5LMP3V7IJONALV2KOFL4NUU23CJ/https://security.gentoo.org/glsa/202401-03https://support.apple.com/kb/HT214035https://support.apple.com/kb/HT214036https://www.debian.org/security/2023/dsa-5584
2023-12-08
Published